Cloud DLP
1. Data discovery and classification of (sensitive) data in Cloud Storage, BigQuery and Datastore.
2. Supports "streaming API" to support additional data sources and custom workloads
Data identification using "built-in" and "custom" infotypes.
Also performs automatic classification, masking, tokenization and transformation of sensitive data elements (such as PII data)
Data Catalog
To find, curate and use metadata to describe data assets in the cloud.
Use Data Catalog to search for data assets and tag the assets with metadata.
CMEK - Generate and manage encryption keys using Cloud KMS. Helps to rotate encryption keys regularly
CSEK - Create and manage your own encryption keys and then provide to Google Cloud. You need your own BYOK solution.
Cloud External Key Manager (Cloud EKM) - This lets you achieve a secure hold-your-own-key (HYOK) model for key management.
Cloud KMS - Software-backed encryption keys or FIPS 140-2 Level 3 validated HSM.
Cloud Audit logs - To view administrator activity and key use logs.
Cloud Monitoring - To ensure proper use of keys.
Study Notes
1. Implied firewall rules on a VPC network - A rule that allows all outbound connections and a rule that denies all inbound connections.
The article provides valuable insights into preparing for the Google Cloud Professional Cloud Security Engineer certification by covering cloud security principles, identity management, data protection, compliance requirements, and security best practices within Google Cloud Platform. It helps readers understand the skills needed to secure cloud-based infrastructures effectively.
ReplyDeleteThe focus on cloud security architecture, risk management, and securing cloud resources makes this topic highly relevant to Cloud Computing Projects. Understanding security controls and governance mechanisms is essential for designing reliable and secure cloud environments.
ReplyDeleteAnother valuable takeaway is the emphasis on cloud-specific security mechanisms such as IAM, encryption, risk assessment, compliance management, and threat mitigation. These concepts closely align with Cloud Security Projects, where protecting cloud infrastructure and ensuring secure service delivery are primary objectives.
ReplyDelete